Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A DevOps engineer needs to manage configuration files across a fleet of Amazon EC2 instances running Amazon Linux. The configuration files must be updated whenever they change in an S3 bucket. Which AWS service is most suitable for this task?

⚠ Common exam trap

Watch out — candidates often confuse AWS Config (which only audits and records configuration changes) with Systems Manager State Manager (which actively enforces and applies desired configurations), leading them to select AWS Config as the answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Systems Manager State Manager

AWS Systems Manager State Manager is the most suitable service because it provides a configuration management solution that can automatically apply and maintain the desired state of EC2 instances. It can be configured to run associations on a schedule or in response to events, such as changes to an S3 bucket, using an AWS Lambda trigger or EventBridge rule to invoke the association. This ensures that configuration files are updated whenever they change in the S3 bucket, without requiring manual intervention or a full configuration management platform.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS OpsWorks for Chef Automate

    Why it's wrong here

    AWS OpsWorks for Chef Automate is a fully managed Chef server, but to use it you must author and maintain Chef cookbooks, manage run lists, and set up Chef clients on every instance. While it can enforce configuration files, it requires a separate configuration-management platform and Chef expertise, making it heavy-weight compared to Systems Manager's SSM documents. It also lacks native integration with IAM instance profile roles for simple, agent-based desired state management, so it is overkill for a basic 'keep these files correct' scenario.

  • ✓

    AWS Systems Manager State Manager

    Why this is correct

    AWS Systems Manager State Manager is the correct choice because it creates State Manager associations that run SSM documents on a schedule to enforce and update configuration files across your managed instances. You can specify the exact content and location of files using SSM documents like AWS-RunShellScript or AWS-ApplyAnsibleModules, and the association will ensure that state stays consistent, remediating drift automatically. It supports targeting by tags, integration with Parameter Store for values, and granular rate controls, making it a native, agent-based configuration management service.

  • ✗

    AWS CloudFormation

    Why it's wrong here

    AWS CloudFormation is an infrastructure-as-code service that provisions AWS resources, such as EC2 instances, through stacks, and it can only bootstrap configuration at launch time via cfn-init, user data, or AWS::CloudFormation::Init. Once an instance is running, CloudFormation does not continuously monitor or correct configuration file content unless you trigger a stack update and recreate the resource. It is a deployment and provisioning tool, not a configuration management system for ongoing drift correction, so it cannot meet the requirement to manage configuration files across existing instances.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is an assessment and compliance service that records resource configuration changes and evaluates them against managed or custom rules. It can detect that a configuration file is out of compliance and even trigger a Systems Manager Automation document to remediate it, but Config itself does not manage or write the configuration files. Its role is governance, auditing, and visibility, not the continuous application of a desired state, so using it alone would leave your configuration files unmanaged.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.